News Room
16
Share
ShinyHunters Resumes Exploitation of Oracle PeopleSoft via WAF Bypass Technique
criticalZero-Day Exploits

ShinyHunters Resumes Exploitation of Oracle PeopleSoft via WAF Bypass Technique

The ShinyHunters extortion group is actively bypassing WAF protections to exploit the critical Oracle PeopleSoft CVE-2026-35273 vulnerability. This follows a surge in zero-day activity throughout September 2026.

27 September 2026Last updated 27 September 20264 min readBleeping Computer
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-35273
Source:
Bleeping Computer
Read Time:
4 min

Executive Summary

As of September 26, 2026, the notorious extortion gang known as ShinyHunters has been observed utilizing sophisticated URL-encoding techniques to circumvent Web Application Firewall (WAF) rules. These rules were originally implemented to mitigate the critical remote code execution (RCE) vulnerability tracked as CVE-2026-35273 within Oracle PeopleSoft suites. This development marks a significant escalation in the threat landscape, as attackers continue to weaponize previously disclosed vulnerabilities despite vendor-provided mitigations.

Threat Analysis

ShinyHunters has demonstrated a persistent interest in the PeopleSoft ecosystem. By leveraging a URL-encoding obfuscation method, the group is successfully bypassing standard signature-based detection mechanisms. This allows them to deliver malicious payloads to vulnerable, unpatched, or improperly secured PeopleSoft servers. The group's primary objective remains large-scale data exfiltration for extortion purposes, targeting organizations that have failed to fully remediate the underlying flaw.

Technical Details

The vulnerability, CVE-2026-35273, is a critical RCE flaw that allows unauthenticated attackers to execute arbitrary code on the underlying server. The recent bypass technique involves manipulating the request structure through specific URL-encoding patterns that the WAF fails to normalize before inspection. Once the WAF is bypassed, the exploit payload triggers the vulnerable component in the PeopleSoft application, granting the attacker unauthorized access to the system's backend and sensitive database contents.

Attribution Assessment

Attribution is assigned to the ShinyHunters group based on the TTPs (Tactics, Techniques, and Procedures) observed in recent data theft campaigns. The group has a documented history of targeting enterprise-grade software suites and utilizing creative bypass methods to maintain access to high-value targets. Their current focus on PeopleSoft suggests a strategic shift toward exploiting legacy enterprise infrastructure that may lack robust, updated security controls.

Implications

The ability of threat actors to bypass WAF protections significantly lowers the barrier to entry for exploiting critical vulnerabilities. Organizations relying solely on perimeter defenses like WAFs to mitigate CVE-2026-35273 are currently at high risk. The persistence of this threat underscores the necessity of applying vendor-supplied patches rather than relying on temporary network-level mitigations.

Recommendations

  1. Immediate Patching: Ensure all Oracle PeopleSoft instances are updated to the latest version provided by the vendor to fully remediate CVE-2026-35273.
  2. WAF Configuration Review: Audit WAF rules to ensure they are configured to handle normalized URL-encoded inputs and are not susceptible to simple obfuscation bypasses.
  3. Threat Hunting: Monitor server logs for anomalous URL patterns and unauthorized outbound traffic indicative of data exfiltration.
  4. Access Control: Implement strict network segmentation and restrict access to PeopleSoft management interfaces to trusted IP ranges only.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo